Database/Control plane, storage & DevOps

HPE StoreOnce (authentication bypass): Unauthenticated attacker bypasses authentication on StoreOnce entirely, gaining
Impact
Unauthenticated attacker bypasses authentication on StoreOnce entirely, gaining full control of the backup appliance. Backup systems hold copies of everything and are a primary ransomware target - this is the bug that makes your recovery path attackable.
Who can reach it
Network access to the StoreOnce management interface. No credentials.
What to do
Upgrade StoreOnce Software per HPESBST04847 as a priority. Appliance upgrade with a service window. Verify backup immutability/retention-lock settings while you are there - authentication bypass plus mutable backups is the ransomware worst case.
References
Related entries
- HPE StoreOnce (directory traversal information disclosure): Unauthenticated directory traversal disclosing filesCVE-2025-37095 · HPE StoreOnce (directory traversal information disclosure)Critical
- HPE Insight Remote Support (remote code execution): Unauthenticated remote code execution on the Insight RS serverCVE-2025-37099 · HPE Insight Remote Support (remote code execution)Critical
- Linux NFS server (nfsd, nfsd4_spo_must_allow): nfsd4_spo_must_allow examines NFSv4 compound state without firstCVE-2025-38430 · Linux NFS server (nfsd, nfsd4_spo_must_allow)Critical
- Linux NFS server (nfsd, nfsd_set_fh_dentry): A refcount leak in the pseudo-root filehandle path lets a client drive theCVE-2025-40212 · Linux NFS server (nfsd, nfsd_set_fh_dentry)Critical
- Vertiv (stack-based buffer overflow, code execution): A stack overflow gives an attacker code execution on the VertivCVE-2025-41426 · Vertiv (stack-based buffer overflow, code execution)Critical
- Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cards: Authentication bypass plusCVE-2025-46412 · Vertiv Liebert RDU101 (<=1.9.0.0) and Liebert IS-UNITY (<=8.4.1.0) communication cardsCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.